1. Data controller
The data controller responsible for your personal data is Gifty Ltd, Punta Roca 146, Panamá, Provincia de Panamá, Panama. Company registration details available on request.
For data protection enquiries, including requests to exercise your rights, contact [email protected]. We aim to respond within the timeframes required by applicable law, typically one month under the EU General Data Protection Regulation (GDPR) where it applies.
2. Scope
This Privacy Policy applies to personal data processed through the Gifty storefront, Control Center, wallet, ticketing, partners programme, GiftyPay top-up flows, and related websites or interfaces operated by us. It does not cover third-party websites, platforms, or payment providers that maintain their own privacy policies.
Where we process personal data solely on behalf of another organisation, we act as a processor and that organisation's privacy notice governs. In most customer-facing activities described here, Gifty acts as the controller.
3. Data we collect
We collect personal data you provide directly, data generated through your use of the Services, and data we receive from service providers where necessary to operate the platform.
3.1 Account and profile data
This may include your name, email address, password hash, locale and region preferences, communication settings, and support ticket content.
3.2 Order and fulfilment data
This includes product selections, order references, delivery status, subscription terms, upgrade instructions, and credentials or account identifiers you submit for fulfilment. We collect only what is necessary to perform the service you purchased.
3.3 Wallet and transaction data
This includes Gifty balance amounts, ledger entries, top-up references, and checkout debits. We do not intentionally store full payment card numbers on Gifty systems when card payments are handled by GiftyPay partners.
3.4 Technical and usage data
This may include IP address, browser type, device identifiers, log files, session data, pages viewed, referral URLs, and security signals used to detect fraud or abuse.
3.5 Communications
If you contact support, legal, or community channels (including Discord where you choose to engage with us), we process the content of those communications and associated metadata.
4. How we use data
We use personal data to create and administer accounts; process orders and deliver digital products; operate the wallet and payment flows; provide Control Center features including subscriptions, IPTV access, and partners tools; handle support tickets; prevent fraud and secure the platform; comply with legal obligations; improve our services; and communicate with you about orders, security, or policy changes.
We do not sell your personal data. We do not use upgrade credentials for marketing purposes or retain them longer than necessary for fulfilment, dispute handling, and legal compliance.
5. Legal bases (GDPR)
Where the GDPR applies, we rely on one or more of the following legal bases: performance of a contract (to provide the Services you request); legitimate interests (to secure the platform, prevent fraud, improve services, and communicate about your account, balanced against your rights); legal obligation (tax, accounting, regulatory, and law-enforcement requests); and consent where required (for example, certain marketing cookies or optional communications where consent is the appropriate basis).
You may withdraw consent at any time where processing is consent-based, without affecting the lawfulness of processing before withdrawal. Where we rely on legitimate interests, you may object as described in Section 12.
6. Account credentials handling
When you purchase an upgrade that requires access to an existing third-party account, you may submit login credentials or related information. We use this data only to perform the ordered service, troubleshoot delivery issues, and handle disputes or legal requests as necessary.
Credentials are transmitted over encrypted connections, access is restricted on a need-to-know basis, and retention is limited in accordance with our fulfilment and security policies. You should change third-party passwords after fulfilment where practicable. Never share credentials with unofficial channels outside Gifty's authenticated flows.
7. Payments and GiftyPay
Payments and wallet top-ups may be processed by GiftyPay and underlying payment service providers, including cryptocurrency processors and card acquirers. Those providers may collect billing details, transaction identifiers, wallet addresses, device risk data, and verification information under their own privacy policies.
Gifty receives confirmation data necessary to credit your balance, reconcile orders, and prevent fraud, such as payment status, amounts, timestamps, and limited payer references. We do not publish or expose full card numbers in the Control Center or support tools.
9. International transfers
Gifty is established in Panama. Some service providers may process data in other countries, including within the European Economic Area (EEA). Where required by applicable law, we implement appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other lawful transfer mechanisms.
You may request further information about transfers and safeguards by contacting [email protected].
10. Retention
We retain personal data only as long as necessary for the purposes described in this Policy, including providing the Services, maintaining business records, resolving disputes, enforcing agreements, and meeting legal retention requirements.
Indicative periods: account profile data for the life of the account plus a limited period after closure; order and billing records typically up to seven (7) years where required for tax and accounting; upgrade credentials for the minimum period needed for fulfilment and dispute windows, then deleted or irreversibly masked where feasible; support tickets for a period aligned with case management needs; security logs for a shorter operational window unless needed for investigations.
11. Security
We implement technical and organisational measures designed to protect personal data against unauthorised access, alteration, disclosure, or destruction. Measures may include encryption in transit, access controls, logging, segregation of duties, and vendor security review.
No method of transmission or storage is completely secure. You play an important role by using a strong unique password, enabling available security features, and reporting suspected compromise promptly to [email protected].
12. Your rights
Depending on your location, you may have rights to access, rectify, erase, restrict, or object to certain processing, and to data portability. Where processing is based on consent, you may withdraw consent. You may also lodge a complaint with a supervisory authority.
In Panama, the supervisory authority is the Autoridad Nacional de Transparencia y Acceso a la Información (ANTAI). EU residents may complain to their local authority. To exercise rights, email [email protected] with enough information to verify your identity and describe your request. We may need to retain certain data where we have overriding legal grounds.
14. Marketing communications
We may send service communications about orders, security, wallet activity, and material policy changes without separate marketing consent where permitted by law. Optional promotional emails or newsletters, if offered, will include an unsubscribe mechanism and will be sent only where lawful.
Community announcements may also appear on Discord or other channels you choose to join; those platforms have their own privacy settings.
15. Children's privacy
The Services are not directed to individuals under 18 years of age, and we do not knowingly collect personal data from children. If you believe a child has provided us personal data, contact [email protected] and we will take appropriate steps to delete the information where required.
16. Automated decision-making
We may use automated systems to detect fraud, rate-limit abusive behaviour, or flag suspicious wallet activity. These processes support security and contractual performance and do not produce legal or similarly significant effects on you without human review where required by law.
If you believe an automated decision has materially affected you, contact [email protected] to request human review where applicable.
17. Changes to this Policy
We may update this Privacy Policy to reflect changes in law, technology, or our practices. The "Last updated" date will be revised accordingly. Material changes will be communicated through the website, by email, or via the Control Center where appropriate.
We encourage you to review this Policy periodically. Continued use after an update constitutes acknowledgement of the revised Policy, except where further consent or notice is required by law.
18. Contact
Data controller: Gifty Ltd, Punta Roca 146, Panamá, Provincia de Panamá, Panama. Company registration details available on request.
Data protection and legal enquiries: [email protected]. Phone: +507 6123-4567. Customer support: [email protected] and in-app tickets.
For formal regulatory or law-enforcement correspondence, include sufficient detail to allow us to identify the request and respond within applicable deadlines.
Related documents
Use support tickets for orders and delivery. Use [email protected] for GDPR, regulatory, or formal legal matters.